Description
In ReadDataElement of common.c, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The ReadDataElement function in common.c performs an incorrect bounds check, allowing a local attacker to read memory outside the intended limits. This error can be exploited without requiring additional privileges or user interaction, leading to the disclosure of sensitive data stored in device memory or shared with local applications. Because this flaw is rooted in improper memory handling, it falls under CWE‑120 and represents a classic local information disclosure vulnerability.

Affected Systems

All Android devices that include the vulnerable implementation of common.c are affected, regardless of exact OS version. The flaw is present in any build or update that does not contain the corrected bounds check. While specific version numbers are not documented in the advisory, any unpatched Android release that has not incorporated the recent security update remains at risk.

Risk and Exploitability

The CVSS score is 6.2, indicating moderate severity. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low but nonzero likelihood of widespread exploitation. The attack vector is local; any user or locally installed application can trigger the flaw without user interaction. Consequently, the primary risk is confidentiality loss rather than denial of service or code execution.

Generated by OpenCVE AI on September 20, 2026 at 13:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Android security update that addresses the ReadDataElement bounds check bug.
  • If an update is not immediately available, restrict or disable applications that can invoke the vulnerable function, or quarantine the device from sensitive data until the patch is applied.
  • Monitor device logs and user activity for unexpected data reads and isolate the device from sensitive networks until a fix is deployed.

Generated by OpenCVE AI on September 20, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure via Incorrect Bounds Check in ReadDataElement of Android common.c

Thu, 17 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Bounds Check in Android ReadDataElement

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Bounds Check in Android ReadDataElement

Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In ReadDataElement of common.c, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T16:03:57.993Z

Reserved: 2026-06-23T16:05:58.747Z

Link: CVE-2026-56892

cve-icon Vulnrichment

Updated: 2026-09-15T20:18:40.475Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:24.500

Modified: 2026-09-21T17:19:07.810

Link: CVE-2026-56892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:00:26Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')